Trivy Scanner v0.42.0
Released 2026-09-21. GitHub release
Features
- metrics: classify scan failures, real readiness, queue self-recovery and engine defaults (#110)
- metrics: Expose scanner operational telemetry (#98)
- perf: Trivy scans with durable workers and dedicated Valkey (#106)
Upstream
- feat: restrict TLS cipher suites and curves for FIPS 140 compliance (#109)
Container Image
Multi-arch image (linux/amd64, linux/arm64) signed with cosign.
| Image | Reference |
|---|---|
harbor-scanner-trivy | 8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.42.0 |
Verify the image signature:
cosign verify \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.42.0Verify the SBOM attestation:
cosign verify-attestation \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
--type spdxjson \
8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:75c8e5c5a1998af4b9a01292efc211c359a2590e389713580d09f89e96b4b3baHelm Chart
The chart is released separately - see the chart-v* releases.
To deploy this adapter version with the latest chart:
helm install harbor-scanner-trivy \
oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
--set image.tag=v0.42.0Binaries
Static linux/amd64 and linux/arm64 binaries are attached to this release
(checksums.txt has the SHA256 sums):
| Asset | Contents |
|---|---|
scanner-trivy_linux-<arch>.tar.gz | Harbor scanner adapter v0.42.0 |
trivy_linux-<arch>.tar.gz | Trivy CLI v0.74.0, built from source |